logo

OH-MY-DC: OIDC Misconfigurations in CI/CD

ID: 00b37c89-b8a8-50a7-8d00-3347170b7f55

STIX ID: report--00b37c89-b8a8-50a7-8d00-3347170b7f55

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-28

Author: Aviad Hahami

...
...

Unit 42 analyzed the use of OpenID Connect (OIDC) in CI/CD pipelines and discovered critical misconfigurations that can enable attackers to access cloud resources. The report highlights three main risks—overly permissive identity federation policies, trusting user-controllable claims (and unsafe custom sub formats), and combining poisoned pipeline execution with lax federation—and documents a real-world vendor issue in CircleCI that was remediated; it concludes with recommendations for repository-specific federation rules, strict claim validation, CI hardening, and tooling to detect these misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.